Re: If you work with removing Rootkits you should read this.
From: Matt Gibson (mattg_at_blueedgetech.ca)
Date: 03/10/05
- Next message: jeffrey: "MrxSmb Event ID 3019 and event ID 11708"
- Previous message: Joe: "Re: MyWay.MyBar"
- In reply to: Bigbruva: "If you work with removing Rootkits you should read this."
- Next in thread: Bigbruva: "Re: If you work with removing Rootkits you should read this."
- Reply: Bigbruva: "Re: If you work with removing Rootkits you should read this."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 10 Mar 2005 14:15:47 -0800
Why don't you just run Rootkit revealer from Bart-PE...you'll get mostly the
same level of reporting.
Oh, and rootkit revealer was released shortly after that paper was...many
think in a reponse TO that paper.
Matt Gibson - GSEC
"Bigbruva" <Richardh@dontusethis.ws> wrote in message
news:e%23wCShaJFHA.2936@TK2MSFTNGP15.phx.gbl...
> Hi all
>
> I came across this excellent whitepaper on the Microsoft Research Web
> site.
> It discusses a tool they have developed that will detect Rootkits (or
> Ghostware as they call it), rather like the Sysinternals RootkitRevealer
> but with some very interesting "Out of Box" scanning capability.
>
> http://research.microsoft.com/research/pubs/view.aspx?type=Technical%20Report&id=875
>
> If you work will removing Rootkits etc it looks like we will have a
> Microsoft tool to help, the only question is when?
> From the Web site:
>
> "Strider GhostBuster will be released either as a research prototype or as
> part of Microsoft products. "
>
> Please MS release this tool soon! Pretty please! :-)
>
>
> BB
>
- Next message: jeffrey: "MrxSmb Event ID 3019 and event ID 11708"
- Previous message: Joe: "Re: MyWay.MyBar"
- In reply to: Bigbruva: "If you work with removing Rootkits you should read this."
- Next in thread: Bigbruva: "Re: If you work with removing Rootkits you should read this."
- Reply: Bigbruva: "Re: If you work with removing Rootkits you should read this."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|